๐ฉ๐ช
Blexyel
2026-09-28 10:55:19
(1 week ago)
162.158.88.113 - - [28/Sep/2026:12:55:19 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ...
show more
162.158.88.113 - - [28/Sep/2026:12:55:19 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "cloud.phoenixts.eu"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 17:03:47
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ง๐ช
madeit
2026-09-11 09:30:21
(3 weeks ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 21:59:46
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
๐ช๐ธ
el-brujo
2026-08-29 05:08:32
(1 month ago)
29/Aug/2026:07:08:31.599826 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Aug/2026:07:08:31.599826 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.88.113] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "www.el-hacker.org"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.en
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:31:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:31:16.870683 2026] [security2:error] [pid 5725:tid 5725] [client 162.158.88.113:13672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlebiglebanon.com"] [uri "/.git/config"] [unique_id "aoKcpIngjia8Q7C8Lds8uwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:22:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:22:49.857473 2026] [security2:error] [pid 10679:tid 10679] [client 162.158.88.113:12749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rwabutazafoundation.org"] [uri "/.git/HEAD"] [unique_id "aoJiaRkfPSkdxl0GtteVpAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 18:22:03
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:48:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:48:06.210589 2026] [security2:error] [pid 25851:tid 25851] [client 162.158.88.113:9770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bioemperor.com"] [uri "/.git/config"] [unique_id "aoFBBpdNwyNBPvxTIYoIQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-16 03:12:07
(1 month ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
mawan
2026-07-21 11:46:47
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ธ๐ช
nekopavel
2026-05-25 00:31:29
(4 months ago)
162.158.88.113 - - [25/May/2026:02:31:17 +0200]"GET /wp-admin/install.php HTTP/1.1" 301 162"-" www.f ...
show more
162.158.88.113 - - [25/May/2026:02:31:17 +0200]"GET /wp-admin/install.php HTTP/1.1" 301 162"-" www.futomomo.art "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36""0.000" "-""-" "US"
162.158.88.113 - - [25/May/2026:02:31:24 +0200]"GET /wp-admin/install.php HTTP/1.1" 301 162"-" www.futomomo.art "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36""0.000" "-""-" "US"
162.158.88.113 - - [25/May/2026:02:31:26 +0200]"GET /wp-admin/install.php HTTP/1.1" 301 162"-" www.futomomo.art "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36""0.000" "-""-" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-15 01:44:27
(4 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-11 04:44:48
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:44:33.261775 2026] [security2:error] [pid 25966:tid 25978] [client 162.158.88.113:11896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joeandlane.com"] [uri "/.env.dev"] [unique_id "agFesUQS_rRIn8fJscCWZwAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-05-10 04:17:50
(4 months ago)
UFW:High-frequency access to unused ports
Port Scan